eavictor wrote:
小弟也是最近才剛入手...(恕刪)
你可以試試看,我是這樣設定的:
/ip ipsec proposal auth-algorithms=sha1 enc-algorithms=3des,aes-128,aes-192,aes-256 lifetime=1h pfs-group=none
/ip ipsec peer address=0.0.0.0/0 port=500 auth-method=pre-shared-key generate-policy=yes exchange-mode=main-l2tp
send-initial-contact=yes nat-traversal=yes hash-algorithm=sha1 enc-algorithm=3des dh-group=modp1024
lifetime=1d dpd-interval=2m dpd-maximum-failures=5
/ip firewall filter chain=input action=accept protocol=udp dst-port=4500
/ip firewall filter chain=input action=accept protocol=udp dst-port=1701
/ip firewall filter chain=input action=accept protocol=udp dst-port=500
/ip firewall filter chain=input action=accept protocol=ipsec-esp